The email arrived on a Thursday afternoon, the busiest day at a nine-person design studio. It came from their regular printing supplier, referenced a real project by name, and attached an invoice for $8,400. The only new detail: updated bank account information, “as we’ve switched banks.”

The bookkeeper paid it. Everything looked normal, the amount was believable, and the vendor was one they used every month. Three weeks later the real supplier called asking where their payment was. This is a composite of a scam that plays out the same way in small businesses every single day.

Key takeaways

  • Invoice scams work by impersonating a real vendor you already trust and quietly changing the bank details.
  • The email often references a real project, because the scammer has been reading your inbox.
  • One phone call to a known number would have stopped an $8,400 loss.
  • A simple rule (verify any change of payment details out loud) protects a small team completely.

How the scam actually worked

This was not a random blast. It was targeted, and it started earlier than anyone realized.

a printed invoice with altered bank details highlighted
The only fake detail on the whole page was the account number at the bottom.

Weeks before, someone in the studio had clicked a phishing link and entered their email password on a fake login page. The scammer did not do anything loud with that access. They quietly read the mailbox, learning the studio’s vendors, projects, tone, and payment rhythm.

When they understood the pattern, they crafted an invoice that fit right in. Correct project name, believable amount, familiar supplier, and a plausible reason for the account change. The forgery worked because everything around the fake detail was true.

Good to know

This pattern has a name: business email compromise. It is one of the costliest scams for small companies precisely because it does not look like a scam. There is no scary link and no obvious threat, just a routine-looking invoice.

The moment it could have been caught

There was a five-second window where the whole thing fell apart, and the studio walked right past it.

The email said the supplier had “switched banks.” That single sentence is the entire scam. A change of bank details is the one event that should always trigger a phone call to a number you already have, not the number in the email.

That supplier’s real phone number was already saved in the bookkeeper’s contacts. A 30-second call (“hey, did your bank details change?”) would have ended it. But it was Thursday, the studio was slammed, and the invoice looked routine, so the call never happened. Learning to pause on messages like this is the heart of the guide to spotting a phishing email before you click.

What it cost, beyond the $8,400

The obvious number was the wire transfer. The full bill was larger and messier.

Cost Rough amount Notes
The fraudulent payment $8,400 Wired to the scammer’s account, mostly unrecoverable
Paying the real invoice again $8,400 The actual supplier still needed paying
Staff time on cleanup $1,500+ Days of calls to the bank, police, and vendor
Securing the breached email $400 IT help to reset accounts and check for other access
Trust with the supplier Hard to price An awkward, damaged relationship

Because the money went out as a wire to a mule account, the bank recovered almost none of it. The studio effectively paid for that print job twice, plus the cleanup. For a nine-person business, that is a genuinely painful hit.

The three checks that would have stopped it

None of these are technical. Any small team can adopt all three this week.

1. Call to confirm any change of bank details

This is the golden rule. If an invoice, email, or message changes where money should go, verify it by calling a phone number you already had on file, never the number or link in the new message. Make it a hard, no-exceptions policy.

Tip

When I set this rule up for a friend’s small agency, we wrote it on a sticky note above the bookkeeper’s monitor: “New account number? Pick up the phone.” It has caught two attempts in two years. A sticky note beat an $8,400 loss.

2. Protect the email account with two-factor login

The whole scam started with a stolen email password. Two-factor authentication (a code from an app on top of the password) would have kept the scammer out of the mailbox, and without that inside knowledge the fake invoice never gets written.

3. Slow down on payment requests, especially on busy days

Scammers time their messages for your busiest moments on purpose, because that is when careful checks get skipped. A simple rule that all payments over a set amount get a second person’s eyes adds friction exactly where fraud tries to slip through.

How the recovery went

The studio reported the fraud to the bank immediately, but the money was already gone. They filed a report with the FBI’s Internet Crime Complaint Center, which tracks business email compromise, and reported it to the FTC. Fast reporting occasionally lets a bank freeze funds, so speed is worth it even when the odds are low.

Then they cleaned house: reset every email password, turned on two-factor across the company, and wrote the “call to confirm bank changes” rule into their process. The full sequence of what to do after fraud lands is laid out in the scam recovery steps guide, and the studio worked through nearly all of it.

They came out of it with sturdier habits, but at a steep tuition. The broader picture of how these cons operate lives in the beginner guide to spotting scams and phishing, which is worth sharing with anyone on your team who touches money.

Your afternoon checklist

  • Write a firm rule: any change to vendor bank details gets confirmed by a phone call to a known number.
  • Turn on two-factor authentication for every business email account today.
  • Add a second-person approval step for payments over a set amount.
  • Warn your bookkeeper that scam invoices arrive on the busiest days on purpose.
  • Save your key vendors’ real phone numbers so you never rely on an email’s contact info.
  • Teach the team that “switched banks” is a phrase that always triggers a verification call.
  • If you get hit, report it fast to your bank and to ic3.gov, since speed can occasionally recover funds.

The studio was not careless; it was busy, and busy is where this scam lives. One phone call stood between a normal Thursday and paying an invoice twice, and that call is a habit any small team can build for free.